Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
2023-11-11T01:15:07.357
2024-11-21T08:29:25.480
Modified
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | openvpn | openvpn | ≤ 2.6.6 | Yes |
| Application | openvpn | openvpn_access_server | ≤ 2.11.3 | Yes |
| Application | openvpn | openvpn_access_server | < 2.12.2 | Yes |
| Operating System | debian | debian_linux | 12.0 | Yes |
| Operating System | fedoraproject | fedora | 39 | Yes |